rootpwn

high · CVSS v3 7.5 · EPSS 0.00136

CVE-2026-87839

The Tripzzy WordPress plugin (v<1.5.1) lacks authorization checks on an AJAX endpoint, letting unauthenticated users delete any comment. Thi

Overview

The Tripzzy WordPress plugin (v<1.5.1) lacks authorization checks on an AJAX endpoint, letting unauthenticated users delete any comment. This flaw can erase user-generated content and disrupt site integrity. It is a high‑severity vulnerability that can be exploited without credentials.

Description

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

Impact

Confidentiality: comment data can be removed, affecting content integrity. Integrity: arbitrary comments can be deleted, undermining trust. Availability: repeated deletions could degrade user experience. Site administrators and users are impacted.

Remediation

Update the Tripzzy plugin to version 1.5.1 or later. If update not possible, disable the AJAX endpoint or remove the plugin. Monitor comment logs for unexpected deletions and restore from backups if necessary.

Risk context

Severity is high with CVSS 7.5 and EPSS 0.00136, indicating a low probability but significant impact. Defenders should treat it as a moderate to high priority patch.

Affected products

  • Tripzzy plugin

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
EPSS
0.00136

WordPress plugin unauthenticated comment-deletion authorization high-severity

← All CVEs